Impact
Out of bounds read and write in ANGLE within Google Chrome prior to 148.0.7778.216 allows a remote attacker who has already compromised the renderer process to escape the sandbox and gain elevated privileges on the host. The flaw permits arbitrary memory operations that can corrupt the process state or redirect execution flow, potentially leading to full system compromise. The attack scenario involves a malicious web page that triggers the vulnerability, so a visitor to a compromised site may initiate the exploit once the renderer process is breached.
Affected Systems
Google Chrome across all platforms is affected, specifically versions installed before 148.0.7778.216. The vulnerability is tied to the ANGLE graphics abstraction layer used by the renderer process; any older Chrome installation that has not yet applied the 148.0.7778.216 patch remains vulnerable.
Risk and Exploitability
Chromium rates this issue as High, reflected by a CVSS score of 8.2. The EPSS score is < 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation to date. However, exploitation requires a foothold in the renderer process, typically achieved by visiting a malicious web page. Once inside, the out‑of‑bounds access can be leveraged to escape the sandbox and execute code at the system level, presenting a significant risk to confidentiality, integrity, and availability of affected systems.
OpenCVE Enrichment